SHARE
Facebook X Pinterest WhatsApp

Tech Firms Split on Paying for Security Flaws

Aug 3, 2010

In the ongoing cat-and-mouse game of securing IT software and hardware, vendors are sharply split on the wisdom of paying third-party researchers to bring vulnerabilities to their attention. For some, like Mozilla and HP, paying those fees is just part of doing business. For others, the practice is strictly off limits.

Everyone seems to agree that working with the research community is critical, so what makes the difference? Reporting from the Black Hat security conference, Datamation canvasses security executives at several major IT firms on their approach toward paying researchers for vulnerabilities.


There is an ongoing debate in the IT security community about whether or not it makes sense for software and hardware vendors to pay researchers for finding vulnerabilities. For some vendors like Mozilla and HP (NYSE:HPQ), rewarding researchers is a part of their security model. On the other hand, Microsoft has steadfastly kept to a policy of not paying those who uncover security holes. Networking giant Cisco (NASDAQ:CSCO) has more of a bartering system for rewarding researchers.

The different approaches help to illustrate how each vendor prefers to deal with the security research community. The bottom line though is that vendors all want to be informed of when their software is vulnerable; the only issue is how they work with researchers to actually get that information.



Read the full story at Datamation:


IT Vendors Disagree on Paying for Security Holes

Recommended for you...

Best Internet Security Software
Devin Partida
Mar 23, 2022
HP Wolf Security Report Shows Threat Landscape Getting Scarier
Rob Enderle
Oct 15, 2021
Microsoft Gets Rid Of Passwords: I Can Almost Hear Angels Singing
Rob Enderle
Sep 17, 2021
The Coming AI Threats We Aren’t Prepared For
Rob Enderle
Aug 27, 2021
Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.